Hello

I see many SSL_connect error for different domains which mail service hosted at microsoft:

Apr 28 10:32:12 srv1 postfix/smtp[18296]: SSL_connect error to irs-ro.mail.eo.outlook.com[213.199.154.87]:25: lost connection Apr 28 10:32:12 srv1 postfix/smtp[18296]: 3lbZRv0VXQz1lvjB: to=<xxxxx...@irs.ro>, relay=irs-ro.mail.eo.outlook.com[213.199.154.87]:25, delay=1.1, delays=0.14/0.37/0.56/0, dsn=4.7.5, status=deferred (Cannot start TLS: handshake failure)

After a few tries postfix send the message in plain.

Looked at the mailing list archive I resolved with smtp_tls_policy_maps = hash:/etc/postfix/tls_policy:

tls_policy:
irs.ro          may protocols=TLSv1 ciphers=medium exclude=3DES:MD5


But all this domains have MX record pointed to something.othersomething.outlook.com, so I wonder if there is a method to apply this policy like that:

[.outlook.com]:25 may protocols=TLSv1 ciphers=medium exclude=3DES:MD5

    Thanks,
    Levi



postfix-3.1.20150421

#postconf -n

alias_database = hash:/etc/postfix/aliases
alias_maps = hash:/etc/mailman/aliases, hash:/etc/postfix/aliases
append_at_myorigin = no
append_dot_mydomain = no
authorized_submit_users = root
broken_sasl_auth_clients = yes
command_directory = /usr/sbin
compatibility_level = 0
config_directory = /etc/postfix-amail
content_filter = amavis:[127.0.0.1]:10120
daemon_directory = /usr/libexec/postfix
data_directory = /var/lib/postfix-amail
default_destination_recipient_limit = 30
dovecot_destination_recipient_limit = 1
enable_long_queue_ids = yes
html_directory = /usr/share/doc/postfix-2.9.4-documentation/html
inet_interfaces = 127.0.0.1 176.223.199.54
inet_protocols = ipv4
mail_owner = postfix
mailbox_size_limit = 0
mailq_path = /usr/bin/mailq.postfix
manpage_directory = /usr/share/man
maximal_backoff_time = 8000s
message_size_limit = 25480000
minimal_backoff_time = 1800s
multi_instance_enable = yes
multi_instance_name = postfix-amail
mydestination = $myhostname, localhost.$mydomain, localhost
mydomain = $myhostname
myhostname = srv1.xxxxxxxx.ro
mynetworks = 127.0.0.1
myorigin = $mydomain
newaliases_path = /usr/bin/newaliases.postfix
non_smtpd_milters = $smtpd_milters
opendkim_milter = inet:localhost:8891
opendmarc_milter = inet:localhost:8893
policy-spf_time_limit = 3600s
postscreen_access_list = permit_mynetworks, cidr:/etc/postfix/postscreen_access.cidr, cidr:/etc/postfix/postscreen_spamhaus.cidr
postscreen_bare_newline_action = ignore
postscreen_bare_newline_enable = yes
postscreen_blacklist_action = drop
postscreen_cache_retention_time = 7d
postscreen_dnsbl_action = enforce
postscreen_dnsbl_sites = rbl.abuse.ro*2 zen.spamhaus.org*3 b.barracudacentral.org*3 bl.spameatingmonkey.net*2 bl.mailspike.net*1 bl.spamcop.net*1 swl.spamhaus.org*-4 list.dnswl.org=127.[0..255].[0..255].0*-2 list.dnswl.org=127.[0..255].[0..255].1*-3 list.dnswl.org=127.[0..255].[0..255].[2..255]*-4
postscreen_dnsbl_threshold = 3
postscreen_dnsbl_whitelist_threshold = -1
postscreen_dnsbl_action = enforce
postscreen_dnsbl_sites = rbl.abuse.ro*2 zen.spamhaus.org*3 b.barracudacentral.org*3 bl.spameatingmonkey.net*2 bl.mailspike.net*1 bl.spamcop.net*1 swl.spamhaus.org*-4 list.dnswl.org=127.[0..255].[0..255].0*-2 list.dnswl.org=127.[0..255].[0..255].1*-3 list.dnswl.org=127.[0..255].[0..255].[2..255]*-4
postscreen_dnsbl_threshold = 3
postscreen_dnsbl_whitelist_threshold = -1
postscreen_greet_action = enforce
postscreen_greet_banner = $smtpd_banner/Postscreen enabled
postscreen_non_smtp_command_action = ignore
postscreen_non_smtp_command_enable = yes
postscreen_pipelining_action = ignore
postscreen_pipelining_enable = yes
proxy_read_maps = $local_recipient_maps, $mydestination, $virtual_alias_maps, $virtual_alias_domains, $virtual_mailbox_maps, $virtual_mailbox_domains, $relay_recipient_maps, $relay_domains, $canonical_maps, $sender_canonical_maps, $recipient_canonical_maps, $relocated_maps, $transport_maps, $mynetworks,
queue_directory = /var/spool/postfix-amail
queue_run_delay = 1200s
receive_override_options = no_address_mappings
relay_domains = proxy:mysql:/etc/postfix/mysql-virtual_relaydomains.cf
relay_recipient_maps = proxy:mysql:/etc/postfix/mysql-virtual_relayrecipientmaps.cf
relayhost =
sample_directory = /etc/postfix
sendmail_path = /usr/sbin/sendmail.postfix
setgid_group = postdrop
smtp_sasl_tls_security_options = noanonymous
smtp_tls_CAfile = $smtpd_tls_CAfile
smtp_tls_cert_file = $smtpd_tls_cert_file
smtp_tls_key_file = $smtpd_tls_key_file
smtp_tls_loglevel = 1
smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
smtp_tls_security_level = may
smtp_tls_session_cache_database = btree:$data_directory/smtp_tls_session_cache
smtp_use_tls = yes
smtpd_client_restrictions =
smtpd_data_restrictions =
smtpd_delay_reject = yes
smtpd_helo_required = yes
smtpd_helo_restrictions = reject_invalid_helo_hostname, reject_non_fqdn_helo_hostname
smtpd_milters = $opendkim_milter,$opendmarc_milter
smtpd_recipient_restrictions = permit_mynetworks, reject_unauth_destination, check_client_access mysql:/etc/postfix/mysql-virtual_client.cf, check_sender_access mysql:/etc/postfix/mysql-virtual_sender.cf, check_recipient_access mysql:/etc/postfix/mysql-virtual_recipient.cf, reject_non_fqdn_sender, reject_non_fqdn_recipient, reject_unknown_sender_domain, reject_unknown_recipient_domain, reject_unauth_pipelining, reject_unlisted_sender, check_reverse_client_hostname_access pcre:/etc/postfix/fqrdns.pcre
smtpd_sasl_auth_enable = yes
smtpd_sasl_authenticated_header = no
smtpd_sasl_path = /var/spool/postfix/private/auth
smtpd_sasl_security_options = noanonymous
smtpd_sasl_type = dovecot
smtpd_sender_restrictions =
smtpd_tls_CAfile = /etc/pki/tls/certs/CAcert.org_Root_Certificate.pem
smtpd_tls_ask_ccert = yes
smtpd_tls_auth_only = no
smtpd_tls_cert_file = /etc/pki/tls/certs/srv1.xxxxxxxx.ro.pem
smtpd_tls_exclude_ciphers = EXPORT, LOW
smtpd_tls_key_file = /etc/pki/tls/private/srv1.xxxxxxxxx.ro.privatekey.pem
smtpd_tls_loglevel = 1
smtpd_tls_received_header = yes
smtpd_tls_security_level = may
smtpd_tls_session_cache_database = btree:$data_directory/smtpd_tls_session_cache
smtpd_use_tls = yes
smtputf8_enable = no
tls_random_source = dev:/dev/urandom
transport_maps = proxy:mysql:/etc/postfix/mysql-virtual_transports.cf
undisclosed_recipients_header = To: undisclosed-recipients:;
unknown_local_recipient_reject_code = 550
virtual_alias_domains = lists.xxxxxxxxx.ro
virtual_alias_maps = hash:/etc/mailman/virtual-mailman, proxy:mysql:/etc/postfix/mysql-virtual_forwardings.cf, proxy:mysql:/etc/postfix/mysql-virtual_email2email.cf
virtual_gid_maps = static:5000
virtual_mailbox_base = /var/vmail
virtual_mailbox_domains = proxy:mysql:/etc/postfix/mysql-virtual_domains.cf
virtual_mailbox_maps = proxy:mysql:/etc/postfix/mysql-virtual_mailboxes.cf
virtual_transport = dovecot
virtual_uid_maps = static:5000


Reply via email to